| Vulnerability Name: | CVE-2013-2752 (CCN-88206) | ||||||||
| Assigned: | 2013-10-22 | ||||||||
| Published: | 2013-10-22 | ||||||||
| Updated: | 2019-07-18 | ||||||||
| Summary: | Cross-site request forgery (CSRF) vulnerability in frontview/lib/np_handler.pl in NETGEAR ReadyNAS RAIDiator before 4.1.12 and 4.2.x before 4.2.24 allows remote attackers to hijack the authentication of users. | ||||||||
| CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
| CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C)
7.8 High (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-352 | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: CCN Type: BugTraq Mailing List, Tue Oct 22 2013 - 08:33:35 CDT [CVE-2013-2751, CVE-2013-2752] NETGEAR ReadyNAS Remote Root Source: MITRE Type: CNA CVE-2013-2752 Source: OSVDB Type: Broken Link 98825 Source: CCN Type: NetGear ReadyNAS RAIDiator 4.1.x Download Web Site NetGear ReadyNAS RAIDiator 4.1.x Download Source: CCN Type: NetGear ReadyNAS RAIDiator 4.2.x Download Web Site NetGear ReadyNAS RAIDiator 4.2.x Download Source: MISC Type: Patch, Vendor Advisory http://www.readynas.com/?p=7002 Source: CCN Type: BID-62059 NetGear RAIDiator Cross Site Request Forgery and Command Injection Vulnerabilities Source: CCN Type: Tripwire Web Site Security Advisory: NETGEAR ReadyNAS Source: MISC Type: Third Party Advisory http://www.tripwire.com/register/security-advisory-netgear-readynas/ Source: CCN Type: Tripwire The State of Security Web Site ReadyNAS Flaw Allows Root Access from Unauthenticated HTTP Request Source: MISC Type: Third Party Advisory http://www.tripwire.com/state-of-security/vulnerability-management/readynas-flaw-allows-root-access-unauthenticated-http-request/ Source: XF Type: UNKNOWN netgear-readynas-cve20132752-cmd-execution(88206) Source: CCN Type: Packet Storm Security [10-28-2013] Netgear ReadyNAS Remote Command Execution Source: CCN Type: NetGear ReadyNAS RAIDiator Web Site NetGear ReadyNAS RAIDiator | ||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||